The UK government recently announced a Data Reform Bill which considers reducing data protection and privacy rules.
Changes would be made to the UK General Data Protection Regulation (UK GDPR), which came into force following Brexit as a continuation of the General Data Protection Regulation (GDPR) – which was implemented across Europe in May 2018.
The new UK bill proposes to reduce compliance for companies and make it easier to use personal data, as well as reform the Information Commissioner’s Office (ICO). The UK’s Department for Digital, Culture, Media and Sport (DCMS) leads this legislative agenda. Current compliance models may not need to be overhauled but the new legislation could mean that UK organisations have a more flexible approach to data protection compliance.
Since 2021, under the UK GDPR, the UK has allowed the free flow of personal data between the UK and EU. There is debate as to whether these changes will affect the current agreement with the EU. Specifically, the reduction in protection of personal data and the prioritisation of countries which the EU deems inadequate, could compromise the decision and encourage firms not to host personal data in the UK.
The new bill has not yet been decided. Current suggestions seem to indicate there will be less choice for users and less accountability for businesses. More attention to and concern for data protection is paramount to protect the individual, so it appears illogical that the UK should be the only country in Europe with plans to move in the opposite direction. Particularly when the UK is trying to regain its standing and grow international trading following Brexit – as any negative changes could weaken the ease of and opportunities for doing business.
